VDB

CVE-2025-7329

CVE-2025-7329 PUBLISHED CVSS 8.5 HIGH

A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.

EPSS 0.01% · 1.1th percentile

Risk Scores

CVSS 4.0
8.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.01%
1.1th percentile

Affected Products

VendorProductVersions
rockwellautomation1783-natr_firmware0
Rockwell AutomationComms - 1783-NATRVersion 1.006 and prior

Timeline

  • Oct 14, 2025 CVE Published
  • Oct 14, 2025 CVE Updated
  • Oct 15, 2025 EPSS Score
  • Oct 21, 2025 EPSS Score
  • Oct 21, 2025 PoC Published
  • Oct 27, 2025 EPSS Score
  • Nov 2, 2025 EPSS Score
  • Nov 8, 2025 EPSS Score
  • Nov 15, 2025 EPSS Score
  • Nov 21, 2025 EPSS Score
  • Nov 27, 2025 EPSS Score
  • Dec 3, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›